Become a MacRumors Supporter for $50/year with no ads, ability to filter front page stories, and private forums.

etaleb

macrumors 6502a
Original poster
Apr 7, 2012
599
27
Very strange, but I purchased something online today (an esim service) and I paid with Apple Pay and the receipt actually has the last four digits of my credit card. I thought Apple Pay used to more the credit card number completely and some other four digits should appear. Thanks
 
Perhaps it's a coincidence? My grocery store receipts using Apple Pay in person --with two different cards --and multiple visits with each card, show last four digits that differ from the actual card numbers. And each time a particular card was used, the same four digits appear on the receipt. [Edit: I have two receipts using one of those cards with Apple Pay at a different store and the last four are different from the grocery, but again the same last four on both receipts.] [Also, since it was an online payment, are you sure it used Apple Pay instead of your browser's saved card information?]
 
Last edited:
My wallet settings clearly show my last four digits which Apple creates to be a different number so this is very strange. Definitely not a coincidence with me so I wondered if Apple is doing things differently now
 
Oh, I wasn't even looking for the number that Apple Pay creates, found deeper in wallet. Wallet shows my physical card number and the Apple Pay number, which is different on phone versus my Apple Watch for the same card, but even those four last digits are different from the receipts, so who knows.
 
Oh, I wasn't even looking for the number that Apple Pay creates, found deeper in wallet. Wallet shows my physical card number and the Apple Pay number, which is different on phone versus my Apple Watch for the same card, but even those four last digits are different from the receipts, so who knows.
I just checked and you are right. The numbers are different from my watch and phone.
 
If I had to make a guess, the website does get the last four digits of the real card. I just started the process of using Apple Pay on a website to buy something and the website does get the last four digits of the real number. This is, seemingly, confirmed in the Apple Security Guide and how it works when actually using it:


The app requests any pieces of information it needs to process and fulfill the transaction, such as the billing and shipping address, and contact information. The app then asks iOS, iPadOS, macOS, or watchOS to present the Apple Pay sheet, which requests information for the app and other necessary information, such as the card to use.

So, the first thing presented in the Apple Pay sheet is the list of cards you have registered. Note that that list has the image of the card and shows the last four digits of the card. So merchant has that info for presentation purposes and could (seemingly) use it to use on the receipt. That info is in the card information section in Wallet for the card.

But the fake number is used for purchase: once a user approves a transaction, a purchase token is sent back to the user, payment information/token is generated in Secure Enclave and sent to AP servers and then the merchant, all using the device-specific card number.

(Last AP purchase not in person was last year for me and never paid attention, so, YMMV. Sub "app" with "website" above as the process is basically the same, just some different details to deal with web things)
 
Last edited:
  • Like
Reactions: CharlesShaw
Register on MacRumors! This sidebar will go away, and you'll see fewer ads.